StarRocks configuration parameters
To configure the service, use the following configuration parameters in ADCM.
|
NOTE
|
| Parameter | Description | Default value |
|---|---|---|
Service user |
Service user account name. It is preconfigured with the |
service_user |
Service user password |
Service user account password |
— |
| Parameter | Description | Default value |
|---|---|---|
authentication_ldap_simple_server_host |
LDAP server hostname or IP address |
— |
authentication_ldap_simple_server_port |
LDAP server port |
— |
authentication_ldap_simple_bind_root_dn |
Distinguished Name (DN) of the LDAP account used to bind to the LDAP server |
— |
authentication_ldap_simple_bind_root_pwd |
Password of the LDAP account used to bind to the LDAP server |
— |
authentication_ldap_simple_bind_base_dn |
Base Distinguished Name (DN) from which StarRocks searches for user accounts |
— |
authentication_ldap_simple_user_search_attr |
LDAP attribute used to search for a user account. Typically, this is the |
— |
authentication_ldap_simple_ssl_conn_allow_insecure |
Specifies whether StarRocks allows insecure SSL connections to the LDAP server without verifying the server certificate |
— |
authentication_ldap_simple_ssl_conn_trust_store_path |
Path to the trust store containing the certificates trusted for SSL connections to the LDAP server |
— |
authentication_ldap_simple_ssl_conn_trust_store_pwd |
Password for the trust store used to verify the LDAP server certificate |
— |
| Parameter | Description | Default value |
|---|---|---|
ssl_keystore_location |
Path to the keystore containing the SSL certificate and private key |
— |
ssl_keystore_password |
Password for the SSL keystore |
— |
ssl_key_password |
Password for the private key stored in the SSL keystore |
— |
ssl_force_secure_transport |
Specifies whether StarRocks requires secure transport for client connections |
— |
| Parameter | Description | Default value |
|---|---|---|
ranger.plugin.starrocks.service.name |
Name of the StarRocks service in Apache Ranger |
<ADH_cluster_name_normalized>_starrocks_id_<number> |
ranger.plugin.starrocks.policy.rest.url |
URL of the Apache Ranger Policy Manager REST API |
http://<Ranger host name>:6080 |
ranger.plugin.starrocks.policy.rest.ssl.config.file |
Path to the SSL configuration file used for connecting to the Apache Ranger Policy Manager |
/etc/starrocks/fe/conf/ranger-policymgr-ssl.xml |
ranger.plugin.starrocks.policy.pollIntervalMs |
Interval in milliseconds between StarRocks policy synchronization requests to Apache Ranger |
30000 |
| Parameter | Description | Default value |
|---|---|---|
xasecure.audit.is.enabled |
Enables Ranger audit |
true |
xasecure.audit.solr.is.enabled |
Specifies whether audit events are sent to Apache Solr |
true |
xasecure.audit.solr.solr_url |
URL of the Apache Solr server used to store StarRocks audit events |
http://<Solr host name>:8983/solr/ranger_audits |
xasecure.audit.hdfs.is.enabled |
Specifies whether audit events are stored in HDFS |
false |
xasecure.audit.hdfs.config.destination.directory |
HDFS directory where StarRocks audit events are stored |
— |
xasecure.audit.destination.solr |
Specifies whether Solr is enabled as an audit event destination |
true |
xasecure.audit.destination.solr.urls |
Comma-separated list of Solr server URLs used as audit event destinations.
Leave this property value empty or set it to |
— |
xasecure.audit.destination.solr.batch.filespool.dir |
Local directory used to spool audit events before they are sent to Solr |
/srv/ranger/starrocks_plugin/audit_solr_spool |
xasecure.audit.destination.solr.force.use.inmemory.jaas.config |
Specifies whether StarRocks uses an in-memory JAAS configuration for authentication to Solr |
false |
xasecure.audit.jaas.Client.loginModuleName |
Name of the JAAS login module used to authenticate the StarRocks audit client |
— |
xasecure.audit.jaas.Client.loginModuleControlFlag |
JAAS control flag that determines how the login module affects authentication |
— |
xasecure.audit.jaas.Client.option.keyTab |
Path to the Kerberos keytab file used by the audit client |
— |
xasecure.audit.jaas.Client.option.principal |
Kerberos principal used by the audit client for authentication |
— |
xasecure.audit.jaas.Client.option.serviceName |
Kerberos service name used by the audit client |
— |
xasecure.audit.jaas.Client.option.useKeyTab |
Specifies whether the audit client uses a Kerberos keytab for authentication |
false |
xasecure.audit.jaas.Client.option.storeKey |
Specifies whether the audit client stores the Kerberos key in the subject credentials |
false |
| Parameter | Description | Default value |
|---|---|---|
xasecure.policymgr.clientssl.keystore |
Path to the SSL keystore used by StarRocks to authenticate with the Ranger Policy Manager |
/etc/ssl/keystore.jks |
xasecure.policymgr.clientssl.truststore |
Path to the SSL truststore used by StarRocks to verify the Ranger Policy Manager certificate |
/etc/ssl/truststore.jks |
xasecure.policymgr.clientssl.keystore.credential.file |
Path to the credential file containing the password for the SSL keystore used by StarRocks to authenticate with the Ranger Policy Manager |
/etc/starrocks/fe/conf/ranger-starrocks.jceks |
xasecure.policymgr.clientssl.truststore.credential.file |
Path to the credential file containing the password for the SSL truststore used by StarRocks to verify the Ranger Policy Manager certificate |
/etc/starrocks/fe/conf/ranger-starrocks.jceks |
| Parameter | Description | Default value |
|---|---|---|
Ranger plugin |
Enables ( |
false |
Custom ranger-starrocks-security.xml |
In this section, you can define values for custom parameters that are not displayed in ADCM UI, but are allowed in the configuration file ranger-starrocks-security.xml |
— |
Custom ranger-starrocks-audit.xml |
In this section, you can define values for custom parameters that are not displayed in ADCM UI, but are allowed in the configuration file ranger-starrocks-audit.xml |
— |
Custom ranger-policymgr-ssl.xml |
In this section, you can define values for custom parameters that are not displayed in ADCM UI, but are allowed in the configuration file ranger-policymgr-ssl.xml |
— |
starrocks-java.yaml |
In this section, you can define values for custom parameters that are not displayed in ADCM UI, but are allowed in the configuration file ranger-policymgr-ssl.xml |
— |
starrocks-java.yaml |
The contents of the starrocks-java.yaml Java security policy file used for StarRocks UDFs |
| Parameter | Description | Default value |
|---|---|---|
be_port |
Port used by the CN component for communication with other StarRocks components |
19060 |
webserver_port |
HTTP port used to access the CN component’s web server |
18040 |
heartbeat_service_port |
Port used by the CN component to receive heartbeat messages |
19050 |
brpc_port |
Port used for communication with other StarRocks components through the BRPC framework |
18060 |
enable_https |
Enables HTTPS for the CN component’s web server |
false |
ssl_certificate_path |
Path to the SSL certificate file used for HTTPS connections |
— |
ssl_private_key_path |
Path to the private key file used for HTTPS connections |
— |
starlet_port |
Port used by the Starlet service for communication with the CN component |
19070 |
storage_root_path |
Root directory for storing data on the CN node |
/var/lib/starrocks/cn-storage |
starlet_cache_dir |
Directory used by Starlet for storing cached data |
/var/lib/starrocks/cn-storage/starlet_cache |
sys_log_dir |
Directory for storing CN component logs |
/var/log/starrocks/cn |
priority_networks |
Specifies the network addresses or subnets that the CN component should prefer for network communication |
— |
spill_local_storage_dir |
Directory used for storing intermediate data spilled to local storage during query execution |
— |
JAVA_OPTS |
Java Virtual Machine options used by the CN component |
— |
kerberos_principal |
Kerberos principal used by the CN component for authentication |
— |
kerberos_keytab |
Path to the keytab file used for Kerberos authentication |
— |
kerberos_relogin_check_interval_second |
Interval, in seconds, at which the CN component checks whether the Kerberos credentials need to be renewed |
60 |
| Parameter | Description | Default value |
|---|---|---|
Add parameter |
In this section, you can define values for custom parameters that are not displayed in ADCM UI, but are allowed in the configuration file cn.conf |
— |
| Parameter | Description | Default value |
|---|---|---|
cn-env.sh |
Script that sets environment variables before the StarRocks CN startup |
— |
Enable custom ulimits |
Applies a custom limits.d file for the CN process (open files, max processes, etc.) |
disabled |
| Parameter | Description | Default value |
|---|---|---|
meta_dir |
Directory used to store FE metadata |
/var/lib/starrocks/fe-meta |
sys_log_dir |
Directory for storing FE component logs |
/var/log/starrocks/fe |
audit_log_dir |
Directory for storing audit logs |
/var/log/starrocks/fe |
http_port |
HTTP port used to access the FE web server |
18030 |
enable_https |
Enables or disables HTTPS for the FE web server |
false |
https_port |
HTTPS port used by the FE web server |
18443 |
rpc_port |
Port used for RPC communication between FE nodes |
19020 |
query_port |
MySQL protocol port used to connect to the FE and submit SQL queries |
19030 |
edit_log_port |
Port used for communication between FE nodes to replicate edit logs |
19010 |
cloud_native_meta_port |
Port used for communication with the cloud-native metadata service |
6090 |
priority_networks |
Specifies the network addresses or subnets that the FE component should prefer for network communication |
— |
run_mode |
Specifies the StarRocks deployment mode |
shared_data |
enable_load_volume_from_conf |
Enables loading storage volume configuration from the FE configuration file |
true |
enable_hadoop_impersonation |
Enables Hadoop impersonation mechanism |
true |
cloud_native_storage_type |
Specifies the type of shared storage used by the StarRocks cluster |
HDFS |
cloud_native_hdfs_url |
Specifies the HDFS URL used as shared storage |
hdfs://adh/starrocks |
JAVA_OPTS |
Java Virtual Machine options used by the FE component |
— |
kerberos_principal |
Kerberos principal used by the FE component for authentication |
— |
kerberos_keytab |
Path to the keytab file used for Kerberos authentication |
— |
kerberos_relogin_check_interval_second |
Interval, in seconds, at which the FE component checks whether the Kerberos credentials need to be renewed |
60 |
| Parameter | Description | Default value |
|---|---|---|
Add parameter |
In this section, you can define values for custom parameters that are not displayed in ADCM UI, but are allowed in the configuration file fe.conf |
— |
| Parameter | Description | Default value |
|---|---|---|
fe-env.sh |
Script that sets environment variables before the StarRocks FE startup |
— |
Enable custom ulimits |
Applies a custom limits.d file for the FE process (open files, max processes, etc.) |
disabled |